Updated on June 20, 2026

Security

Access uses HttpOnly session-token cookies, rate limits on sensitive operations and MFA is available for accounts.

Passwords are stored with strong hashing; refresh tokens are stored as hashes.

MFA logs may contain IP and user agent to prevent abuse and protect accounts.

Report vulnerabilities or incidents to [email protected].